Skip to main content

My apologies to all OGR Forum members for the trouble that
was caused on May 18, 2017 with the Chinese poster attack.



On May 18, 2017, this site was subjected to a series of automated posts made by 6 Chinese "members." I also understand that many of you also got emails related to these posts.

We have taken steps to eliminate the potential for this to ever happen again.

  1. Two-Factor Authentication
    We have initiated the Two-Factor Authentication (2FA) process on this forum. 2FA provides an extra layer of security by allowing you to associate a mobile device with your account.

    If you choose to enable 2FA on your account, you will need to have your mobile device in your possession to sign in. Sign ins are verified through the Google Authenticator App, which presents time-based, verifiable security codes. The Google Authenticator App is available for iOS and Android.

  2. New Member Review
    From now on, someone on the OGR staff will review each new membership application to this forum. A new member will not be able to post anything until we look at the member's profile to make sure it is complete and legitimate. Spammers rarely put accurate name and address information in their applications. Such was the case on the 18th when all of the spammers involved had bogus information in their name and address fields. If we had been manually reviewing and approving new members, they would not have been approved in the first place.

Again, my apologies to those of you that were inconvenienced by this attack. We will do everything we can to make sure it never happens again.

Last edited by Rich Melvin
Original Post

Replies sorted oldest to newest

I did not see any of this or suffer any ill affects. It DOES make me thankful I am no longer a IT Senior System Analyst!!  Even though I today myself do not often deal with it....I see it everyday. My buddy in So Cal got a bug on his PC I have been trying to fix for a week, long distance.  And now my friends at OGR have to spend time and money fighting and fixing destructive behavior by faceless idiots.  This will only get worse as we depend more and more on  the web. My only wish is that someday I get to see these people get what they deserve. 

OGR staff....thanks for all you do. 

Rich thanks for the quick action this morning. I discovered it at 600 am on my phone. I was smart enough not to open but posted warning on the face book .   Only damage done for me was the Yahoo app would not delete them from the Trash folder. and had to uninstall app. I had the same issue last weekend with that App but since I never look into my spam folder and just delete anything in it I will never know what was in my spam folder and my security system would not let me reload the app until Tuesday night. Lap top before I opened any of my emails I made sure all updates and patches were installed and insured I had the latest security updates from Norton before I went to Face book and then to yahoo where I deleted everything in my spam folder and then all that arrived after 100 am in my inbox. about 1500 emails in al,l over 1400 from those six or 7... So why am I posting this.  Rich and other companies are doing their best but it is a two way street. We have to do our part too.

Don't open anything in your spam folder. 

Don't open any attachment from unknown sources. 

If you don't recognize the sender delete and don't open.

Delete any emails that don't have a subject line.

If it dont have .com, .org, .gov stay away and do not open.

The bluf is use common sense.   That helps us and Rich keeping this forum safe.

StPaul posted:

so there is no place in our profile to enable a 2 step verification am I correct?

and that we download a google app to phone instead to accomplish this? or did I miss something in reading your post Rich?

thanks for clarity on this

StPaul, since we just implemented 2FA, I am climbing a learning curve here, just as you are. I am checking with Hoopla Tech Support for the answers to your questions.

Rich,

It is much appreciated how quickly and well you and the OGR team have responded.  The web is a constantly evolving landscape, barriers are put up, the illegitimate find new ways around them.  We all do what we can, it's the nature of the beast, take the good with the bad.   The internet is like the weather, never get comfortable with it, appreciate it for the good it brings, never fully trust it and never turn your back on it.

 

TexasSP posted:

Rich,

 The internet is like the weather, never get comfortable with it, appreciate it for the good it brings, never fully trust it and never turn your back on it.

 

That is truly sage advice. There is NOTHING that is 100% secure in the digital world. It is important that everyone who embarks on the digital journey into cyberspace understand and fully accept that.

Thanks for dealing with this and for the ongoing vigilance. I know that new-member screening is a real pain. The effort is appreciated. 

I do have one question:

Does the new authentication scheme finally eliminate your previous policy of storing (and sometimes emailing) unencrypted user passwords? I know you got angry at me last time I brought this up (a number of years ago) and I do not desire to reopen old wounds, but I am only trying to be helpful and to assess whether I still have to treat the forum as a special case WRT password management. Please do not take offense at the question, but this is important information.

Thanks again.

Last edited by Avanti
Post

OGR Publishing, Inc., 1310 Eastside Centre Ct, Suite 6, Mountain Home, AR 72653
800-980-OGRR (6477)
www.ogaugerr.com

×
×
×
×
Link copied to your clipboard.
×
×